Unauthenticated Blind SQL Injection in mb24api by mbconnectline
CVE-2026-33616
7.5HIGH
Key Information:
- Vendor
Mb Connect Line
- Status
- Vendor
- CVE Published:
- 2 April 2026
What is CVE-2026-33616?
An unauthenticated remote attacker can exploit a blind SQL injection vulnerability in the mb24api endpoint due to improper handling of SQL command elements. This flaw could allow attackers to gain unauthorized access to sensitive data, leading to a potential loss of confidentiality and posing considerable risks to affected systems.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.19.4
mymbCONNECT24 0.0.0 <= 2.19.4
